Главная
Study mode:
on
1
about me
2
Blind XXE
3
Stopping XXE
4
JSON serialization
5
Deserialization Attack Gadgets
6
Custom deserialization attacks
7
Underlying cause
8
Stopping insecure deserialization
9
Templating frameworks
10
Testing for template injection
11
Stopping template injection
12
Common mistakes
13
Server side requests
14
SSRF - Server-Side Request Forgery
15
SSRF - internal services
16
IP-adresses - Blacklisting is hard...
17
Broken URL parsing
18
Protection
19
Subdomain takeover/hijacking
20
Cloud services
21
Example
22
Subdomain takeover - Impact
23
Crowd demo
24
Tricky headers
25
Complicating the attack
26
Stopping web cache poisoning
27
What is this?
28
GraphQL gotchas
29
Resources
Description:
Explore modern web application vulnerabilities in this comprehensive conference talk. Delve into emerging security issues gaining popularity through bug bounty programs. Walk through lesser-known and new vulnerability classes, understanding how they manifest in contemporary web applications. Learn detection techniques and mitigation strategies for these threats. Cover topics including Blind XXE, JSON serialization, deserialization attack gadgets, custom deserialization attacks, template injection, server-side request forgery (SSRF), subdomain takeover, web cache poisoning, and GraphQL gotchas. Gain insights into common mistakes, protection methods, and testing approaches for each vulnerability type. Discover the underlying causes and complexities of these security issues, including tricky headers and IP address blacklisting challenges. Benefit from practical examples, crowd demonstrations, and valuable resources to enhance your web application security knowledge.

Modern Web Application Bugs

NDC Conferences
Add to list